Fintech in Saudi Arabia: SAMA sandbox, CMA permits and how to get licensed
- Payments, lending and open banking usually fall under SAMA
- Crowdfunding and digital advisory usually fall under the CMA
- No regulated service before authorisation
Saudi Arabia has become one of the most active fintech markets in the region. The Saudi Central Bank (SAMA) and the Capital Market Authority (CMA) both run programmes that let new models be tested and licensed, and the number of licensed fintech companies has grown quickly.
Who regulates what
| Model | Usually regulated by |
|---|---|
| Payments, e-wallets, BNPL, consumer and SME finance, open banking | SAMA |
| Equity or debt crowdfunding, digital advisory, investment platforms | CMA |
| Insurance technology | Insurance regulator / SAMA framework |
The sandbox route
Many fintechs start in a regulatory sandbox, where they test their product with real customers under supervision and within limits. After a successful test they can apply for a full license. Some activities can apply for a license directly.
Setting up as a foreign fintech
- Set up a Saudi entity with a MISA license
- Prepare governance, compliance, AML and cybersecurity frameworks
- Plan your capital and team, including Saudi hires and a resident manager
- Choose cloud and data hosting that meets data-protection requirements
- Apply to the sandbox or for a license through the regulator
Only authorised institutions may offer regulated financial services. Do not launch to the public before you have the right permit.
RDO has hands-on experience with SAMA regulations and Saudi fintech rules. We support your launch end to end: entity, licenses, the regulatory application, bank, visas, people and partners.
Sandbox, direct licence or partnership: choosing your route
Before preparing any file, decide how you will reach Saudi customers. The right route depends on your business model, how new it is for the market, and how much regulated activity you will carry out yourself.
- Regulatory sandbox: suited to models that are new to the market or need testing with real customers under supervision. SAMA runs a sandbox for banking, payments and lending innovations, while the CMA runs its FinTech Lab, which grants experimental permits for securities-related models.
- Direct licence: suited to established activities with a clear framework, such as many payment, finance and open banking services, where the applicant can already meet the full requirements.
- Partnership with a licensed institution: some technology companies serve banks or licensed fintechs as vendors rather than offering regulated services themselves. This can be quicker, but the arrangement is usually subject to the partner's outsourcing and risk rules, and it does not allow you to provide the regulated service in your own name.
Fintech Saudi, an initiative launched by SAMA in partnership with the CMA, supports the ecosystem with guidance and programmes, and is a useful first stop for understanding where a model is likely to sit.
Activities to map carefully before you apply
The table above shows the general split between regulators, but several areas need closer attention because the line is not always obvious:
- Debt-based crowdfunding: depending on the structure, it may fall under SAMA's finance rules or under the CMA's framework for debt instruments, so the exact model determines the regulator.
- Insurance technology: insurance supervision now sits with the Insurance Authority, so insurtech models, including digital brokerage and comparison, should be checked against its rules.
- Buy now, pay later and consumer finance: these are regulated finance activities under SAMA, with specific conduct and consumer protection expectations.
- Open banking: account information and payment initiation services follow SAMA's open banking framework and its technical standards.
- Digital assets: treated cautiously; confirm the current regulatory position before marketing anything related to virtual assets.
Document checklist for a SAMA or CMA application
Requirements differ by activity and the regulators update them, but most applications are built around the same core documents. Preparing them early, in a form adapted to Saudi rules rather than copied from another market, usually makes the review smoother.
- A business plan describing the product, target customers, revenue model and multi-year financial projections
- Evidence of capital and sources of funds, in line with the minimum set for the activity
- Corporate documents for the shareholders and the Saudi entity, including the ownership chain and ultimate beneficial owners
- Governance structure: board, committees and key roles such as chief executive, compliance officer and money laundering reporting officer, with fit-and-proper information
- AML/CFT policies, customer due diligence procedures and sanctions screening
- Cybersecurity documentation aligned with the SAMA Cyber Security Framework and the National Cybersecurity Authority's controls
- Technology architecture, outsourcing and cloud arrangements, business continuity and disaster recovery plans
- Data protection measures in line with the Personal Data Protection Law, overseen by SDAIA
- Consumer protection, disclosures, complaints handling and, where relevant, Sharia governance
Prepare key policies so they can be provided in Arabic and use the regulator's own terminology. A policy written for another jurisdiction and lightly edited is one of the most common reasons for repeated questions.
What affects the timeline
There is no single processing time that applies to every fintech. The duration typically depends on the factors below, many of which are within the applicant's control:
- How complete and consistent the file is when first submitted
- How new the model is, and whether the regulator needs time to understand novel risks
- How quickly the team answers follow-up questions and provides clarifications
- The sequencing of corporate steps: MISA registration, commercial registration, bank account and visas
- Hiring key people, including Saudi nationals for required roles, and appointing a resident manager
- Technical readiness, such as security testing and integration with national infrastructure where required
For sandbox participants, the testing period itself adds time, and moving from the sandbox to a full licence is a separate step that should be planned from the start.
Common mistakes foreign fintechs make
- Running a “pilot” with real customers that in practice amounts to a regulated activity before authorisation
- Assuming a licence from another market will be recognised automatically in Saudi Arabia
- Underestimating the people side: compliance, risk and AML roles, local hires and Saudization requirements
- Choosing offshore hosting without first checking data residency and cloud rules
- Leaving the corporate bank account to the end; see our bank account guide
- Treating the sandbox as the finish line instead of planning the route to a full licence from day one
After approval: ongoing compliance
A licence or permit starts a supervisory relationship rather than ending the process. Licensed fintechs typically need to maintain:
- Periodic regulatory reporting, audited financial statements and adequate capital
- Prior approval for significant changes, such as new products, changes of control or key appointments
- Ongoing AML monitoring, transaction screening and suspicious activity reporting
- Cybersecurity reviews, incident reporting and regular testing
- Corporate compliance: commercial registration and MISA renewals, ZATCA obligations including VAT and zakat, GOSI and Qiwa
All of this sits within Vision 2030's Financial Sector Development Program, which aims to build a diverse and digital financial sector. Regulators continue to issue new frameworks, so it pays to monitor updates as a routine task.
RDO has hands-on experience working with SAMA regulations and with the practical steps around a Saudi fintech launch. We coordinate the corporate setup, help prepare and organise the application file, follow up with the relevant authorities and support banking, visas and hiring. Approval decisions rest with the regulator; our focus is helping you submit a clear, complete and well-prepared file. Learn more on our tech and fintech service page.
Frequently asked questions
Can we launch before licensing?
No, only authorised institutions may offer regulated financial services.
Do you have SAMA experience?
Yes, we have hands-on experience with SAMA and Saudi fintech regulations.
Can a foreign fintech work through a Saudi bank instead of getting its own licence?
Sometimes, as a technology provider to a licensed institution. The partner's outsourcing rules usually apply, and you cannot offer the regulated service to the public in your own name without authorisation.
Does our customer data need to be hosted in Saudi Arabia?
It depends on the activity, the type of data and the current SAMA, NCA and personal data protection rules. Check hosting and cloud requirements before choosing a provider, because moving later is costly.
Need help with this in Saudi Arabia?
Tell us about your company and we will map the exact steps, documents and timeline for you. The first consultation is free.
Chat on WhatsApp